Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vqq-fg9c-w77h

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

EPSS

Процентиль: 87%
0.03436
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

CVSS3: 9.8
nvd
около 8 лет назад

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

CVSS3: 9.8
debian
около 8 лет назад

The Zend_Db_Select::order function in Zend Framework before 1.12.7 doe ...

EPSS

Процентиль: 87%
0.03436
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89